Upload log?

Status
Not open for further replies.

Bribaba

Posts: 7   +0
I'm new here and could not find the Upload Log thread so I'm posting here in hope, please redirect if necessary. Thanks.
 
Log uploads

I attach the three logs you requested. Symptoms include Control Panel disappearance and printer not working, though this may be unrelated.
Thanks
Brian
 

Attachments

  • hijackthis.log
    8.8 KB · Views: 5
It can be infections there are the cause to Control Panel and printer problems -


Please download Combofix:
http://subs.geekstogo.com/ComboFix.exe
And save to the desktop.


Open notepad and copy/paste the text in the quotebox below into it:
Name the file as CFScript
and Save it on the desktop

Killall::
Snapshot::
File::
C:\WINDOWS\system32\KHATRA.exe
C:\WINDOWS\system32\winwork.exe

http://www.fromsej.saknet.dk/billeder/cfscript.gif

Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
 
I'm attaching the Combifix logfile as requested. Many thanks for your assistance on this.
Brian
 
Open notepad and copy/paste the text in the codebox below into it:
Name the file as CFScript
and Save it on the desktop

Code:
Killall::
Snapshot::
File::
D:\KHATRA.exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54cde260-250f-11de-96cb-00034768309d}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6c425f0-2e51-11dd-960b-00034768309d}]

http://www.fromsej.saknet.dk/billeder/cfscript.gif

Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
 
Open notepad and copy/paste the text in the codebox below into it:
Name the file as CFScript
and Save it on the desktop

Code:
Killall::

Snapshot::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6c425f0-2e51-11dd-960b-00034768309d}]

http://www.fromsej.saknet.dk/billeder/cfscript.gif

Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post, and tell how things are running now ?

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
 
The log file is attached. The Control Panel has reappeared and the printer flickered briefly into life yesterday but is now refusing to print again. The SD in my camera is also infected, can this be fixed or would it be simpler to buy a new one? Thanks for all.
 
We´ll try to fix it -

Download Flash_Disinfector.exe by sUBs from http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
and save it to your desktop.
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone/Camera.
Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.

Reboot your computer when done.

Attach fresh combofix log

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.
 
I downloaded Flash Disinfector and ran it, and then took a log file which is attached. The PC seems to working ok except for the printer. Thanks again.
 
No. As it briefly worked and then stopped I didn't think it was worth it but I can give it a shot. I was also thinking of finding the Restore point from which it worked, though I'm not sure what the other implication will be.
 
Status
Not open for further replies.
Back